U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-30680

Change History

CVE Translated by MITRE 5/26/2024 9:15:16 PM

Action Type Old Value New Value
Removed Translation
Title: ROS2 Iron Irwini
Description: La vulnerabilidad de inyección de Shell fue descubierta en ROS2 (Robot Operating System 2) Iron Irwini en las versiones ROS_VERSION 2 y ROS_PYTHON_VERSION 3, permite a los atacantes ejecutar código arbitrario, escalar privilegios y obtener información confidencial debido a la forma en que ROS2 maneja la ejecución de comandos de Shell en componentes como intérpretes de comandos o interfaces que procesan entradas externas.

								
						

CVE Rejected by MITRE 5/26/2024 9:15:16 PM

Action Type Old Value New Value

CVE Modified by MITRE 5/26/2024 9:15:16 PM

Action Type Old Value New Value
Changed Description
Shell injection vulnerability was discovered in ROS2 (Robot Operating System 2) Iron Irwini in versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code escalate privileges, and obtain sensitive information due to the way ROS2 handles shell command execution in components like command interpreters or interfaces that process external inputs. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability.
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.
Removed Reference
MITRE http://www.openwall.com/lists/oss-security/2024/04/23/2

								
						
Removed Reference
MITRE http://www.openwall.com/lists/oss-security/2024/04/23/3

								
						
Removed Reference
MITRE http://www.openwall.com/lists/oss-security/2024/04/23/4

								
						
Removed Reference
MITRE http://www.openwall.com/lists/oss-security/2024/04/23/5

								
						
Removed Reference
MITRE https://github.com/yashpatelphd/CVE-2024-30680

								
						
Removed Tag
MITRE disputed